First published: Tue Feb 28 2023(Updated: )
An insufficient session expiration vulnerability exists in the ArubaOS command line interface. Successful exploitation of this vulnerability allows an attacker to keep a session running on an affected device after the removal of the impacted account
Credit: security-alert@hpe.com
Affected Software | Affected Version | How to fix |
---|---|---|
ArubaOS | >=8.6.0.0<=8.6.0.19 | |
ArubaOS | >=8.10.0.0<=8.10.0.4 | |
ArubaOS | >=10.3.0.0<=10.3.1.0 | |
Aruba 7010 | ||
Aruba Networks 7030 | ||
Aruba Networks 7205 | ||
Aruba Networks 7210 | ||
Aruba Networks 7220 | ||
Aruba Networks 7240XM | ||
Aruba Networks 7280 | ||
Aruba Networks 9004 | ||
Arubanetworks 9004-LTE | ||
Aruba Networks 9012 | ||
Aruba Networks MC-VA | ||
Aruba Networks MC-VA-1K | ||
Aruba Networks MC-VA-250 | ||
Aruba Networks MC-VA-50 | ||
Aruba Networks MCR-HW-10K | ||
Arubanetworks MCR-HW-1K | ||
Aruba Networks MCR-HW-5K | ||
Aruba Networks MCR-VA 10K | ||
Aruba Networks MCR-VA-1K | ||
Aruba Networks MCR-VA-50 | ||
Aruba Networks MCR-VA 500 | ||
Aruba Networks MCR-VA 5K | ||
Aruba Networks SD-WAN | >=8.7.0.0-2.3.0.0<=8.7.0.0-2.3.0.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-22771.
The severity of CVE-2023-22771 is medium.
CVE-2023-22771 allows an attacker to keep a session running on an affected device after the removal of the impacted account.
ArubaOS versions ranging from 8.6.0.0 to 8.6.0.19, 8.10.0.0 to 8.10.0.4, and 10.3.0.0 to 10.3.1.0 are affected by CVE-2023-22771.
There is currently no known fix for CVE-2023-22771. It is recommended to apply the necessary patches or updates provided by the vendor.